This issue has been created
There are 8 updates.
 
 
XWiki Platform / cid:jira-generated-image-avatar-f6dc424b-e5d5-406d-ab6d-09505957d03c XWIKI-23734 Closed

Stop exposing Apache Http Client 3 in XWiki Standard API

 
View issue   ยท   Add comment
 

Issue created

 
cid:jira-generated-image-avatar-a44080ff-454e-4551-834a-f7e8996c3aed Thomas Mortagne created this issue on 19/Nov/25 10:50
 
Summary: Stop exposing Apache Http Client 3 in XWiki Standard API
Issue Type: cid:jira-generated-image-avatar-f6dc424b-e5d5-406d-ab6d-09505957d03c Bug
Affects Versions: 16.10.13
Assignee: Unassigned
Components: Old Core
Created: 19/Nov/25 10:50
Priority: cid:jira-generated-image-static-major-4c4e45e9-90f2-4aaf-b4a5-62527684808e Major
Reporter: Thomas Mortagne
Description:

Apache HTTP Client 3 is exposed publicly in XWiki#getHttpClient which is both wrong in general and made even worst because this library has a serious vulnerability.

 
 

8 updates

 
cid:jira-generated-image-avatar-a44080ff-454e-4551-834a-f7e8996c3aed Changes by Thomas Mortagne on 19/Nov/25 10:50
 
Fix Version: 17.0.0-rc-1
Fix Version: 16.10.15
Fix Version: 17.4.8
Documentation in Release Notes: https://www.xwiki.org/xwiki/bin/view/ReleaseNotes/Data/XWiki/17.10.0RC1/#HApacheHttpClient3isnotincludedinXWikiStandardanymore
Documentation: N/A
Assignee: Thomas Mortagne
Resolution: Fixed
Status: Open Closed